<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no"><title>钓鱼指北 Gophish钓鱼平台和邮件服务器搭建 | Zeo's Security Lab</title><meta name="author" content="Zeo"><meta name="copyright" content="Zeo"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="ffffff"><meta name="description" content="0x00 攻防演练钓鱼起因，在大型攻防演练中，传统的web层面Nday打点突破难点变大，于是越来越多的攻击队会加入钓鱼行动中，本文章就常规邮件的钓鱼进行介绍，后续还有IM这种也是很有效的方式。 0x01 搭建Gophish钓鱼平台Gophish 是一个功能强大的开源网络钓框架，安装运行都非常简单。 Github 地址：https:&#x2F;&#x2F;github.com&#x2F;gophish&#x2F;gophish 1、下">
<meta property="og:type" content="article">
<meta property="og:title" content="钓鱼指北 Gophish钓鱼平台和邮件服务器搭建">
<meta property="og:url" content="https://godzeo.github.io/2022/01/20/%E9%92%93%E9%B1%BC%E6%8C%87%E5%8C%97%20Gophish%E9%92%93%E9%B1%BC%E5%B9%B3%E5%8F%B0%E5%92%8C%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA/index.html">
<meta property="og:site_name" content="Zeo&#39;s Security Lab">
<meta property="og:description" content="0x00 攻防演练钓鱼起因，在大型攻防演练中，传统的web层面Nday打点突破难点变大，于是越来越多的攻击队会加入钓鱼行动中，本文章就常规邮件的钓鱼进行介绍，后续还有IM这种也是很有效的方式。 0x01 搭建Gophish钓鱼平台Gophish 是一个功能强大的开源网络钓框架，安装运行都非常简单。 Github 地址：https:&#x2F;&#x2F;github.com&#x2F;gophish&#x2F;gophish 1、下">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp">
<meta property="article:published_time" content="2022-01-20T13:44:10.000Z">
<meta property="article:modified_time" content="2022-11-28T12:25:22.941Z">
<meta property="article:author" content="Zeo">
<meta property="article:tag" content="服务器 运维 安全">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp"><link rel="shortcut icon" href="/img/WX20211124-162855.png"><link rel="canonical" href="https://godzeo.github.io/2022/01/20/%E9%92%93%E9%B1%BC%E6%8C%87%E5%8C%97%20Gophish%E9%92%93%E9%B1%BC%E5%B9%B3%E5%8F%B0%E5%92%8C%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA/"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = { 
  root: '/',
  algolia: undefined,
  localSearch: undefined,
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: '复制成功',
    error: '复制错误',
    noSupport: '浏览器不支持'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '',
  date_suffix: {
    just: '刚刚',
    min: '分钟前',
    hour: '小时前',
    day: '天前',
    month: '个月前'
  },
  copyright: undefined,
  lightbox: 'fancybox',
  Snackbar: undefined,
  source: {
    justifiedGallery: {
      js: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.js',
      css: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.css'
    }
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isAnchor: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
  title: '钓鱼指北 Gophish钓鱼平台和邮件服务器搭建',
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2022-11-28 20:25:22'
}</script><noscript><style type="text/css">
  #nav {
    opacity: 1
  }
  .justified-gallery img {
    opacity: 1
  }

  #recent-posts time,
  #post-meta time {
    display: inline !important
  }
</style></noscript><script>(win=>{
    win.saveToLocal = {
      set: function setWithExpiry(key, value, ttl) {
        if (ttl === 0) return
        const now = new Date()
        const expiryDay = ttl * 86400000
        const item = {
          value: value,
          expiry: now.getTime() + expiryDay,
        }
        localStorage.setItem(key, JSON.stringify(item))
      },

      get: function getWithExpiry(key) {
        const itemStr = localStorage.getItem(key)

        if (!itemStr) {
          return undefined
        }
        const item = JSON.parse(itemStr)
        const now = new Date()

        if (now.getTime() > item.expiry) {
          localStorage.removeItem(key)
          return undefined
        }
        return item.value
      }
    }
  
    win.getScript = url => new Promise((resolve, reject) => {
      const script = document.createElement('script')
      script.src = url
      script.async = true
      script.onerror = reject
      script.onload = script.onreadystatechange = function() {
        const loadState = this.readyState
        if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
        script.onload = script.onreadystatechange = null
        resolve()
      }
      document.head.appendChild(script)
    })
  
      win.activateDarkMode = function () {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = function () {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', 'ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
          if (t === 'dark') activateDarkMode()
          else if (t === 'light') activateLightMode()
        
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    
    const detectApple = () => {
      if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
        document.documentElement.classList.add('apple')
      }
    }
    detectApple()
    })(window)</script><meta name="generator" content="Hexo 6.3.0"><link rel="alternate" href="/atom.xml" title="Zeo's Security Lab" type="application/atom+xml">
</head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231013354.png" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">125</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">46</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">9</div></a></div><hr/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> List</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div></div></div><div class="post" id="body-wrap"><header class="post-bg" id="page-header" style="background-image: url('https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp')"><nav id="nav"><span id="blog_name"><a id="site-name" href="/">Zeo's Security Lab</a></span><div id="menus"><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> List</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div><div id="toggle-menu"><a class="site-page"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">钓鱼指北 Gophish钓鱼平台和邮件服务器搭建</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">发表于</span><time class="post-meta-date-created" datetime="2022-01-20T13:44:10.000Z" title="发表于 2022-01-20 21:44:10">2022-01-20</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">更新于</span><time class="post-meta-date-updated" datetime="2022-11-28T12:25:22.941Z" title="更新于 2022-11-28 20:25:22">2022-11-28</time></span><span class="post-meta-categories"><span class="post-meta-separator">|</span><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/%E5%86%85%E7%BD%91%E5%AE%89%E5%85%A8%E7%A0%94%E7%A9%B6/">内网安全研究</a></span></div><div class="meta-secondline"></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><span id="more"></span>

<h1 id="0x00-攻防演练钓鱼"><a href="#0x00-攻防演练钓鱼" class="headerlink" title="0x00 攻防演练钓鱼"></a>0x00 攻防演练钓鱼</h1><p>起因，在大型攻防演练中，传统的web层面Nday打点突破难点变大，于是越来越多的攻击队会加入钓鱼行动中，本文章就常规邮件的钓鱼进行介绍，后续还有IM这种也是很有效的方式。</p>
<h1 id="0x01-搭建Gophish钓鱼平台"><a href="#0x01-搭建Gophish钓鱼平台" class="headerlink" title="0x01 搭建Gophish钓鱼平台"></a>0x01 搭建Gophish钓鱼平台</h1><p>Gophish 是一个功能强大的开源网络钓框架，安装运行都非常简单。</p>
<p>Github 地址：<a target="_blank" rel="noopener" href="https://github.com/gophish/gophish">https://github.com/gophish/gophish</a></p>
<h3 id="1、下载"><a href="#1、下载" class="headerlink" title="1、下载"></a>1、下载</h3><p><a target="_blank" rel="noopener" href="https://github.com/gophish/gophish/releases">https://github.com/gophish/gophish/releases</a></p>
<p>下载对应的版本</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/8fab9b645d31a766e19380e93d7ba172.png" alt="image-20220117161349446"></p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br></pre></td><td class="code"><pre><span class="line">wget https://github.com/gophish/gophish/releases/download/v0.11.0/gophish-v0.11.0-linux-64bit.zip</span><br><span class="line"></span><br><span class="line">unzip gophish-v0.11.0-linux-64bit.zip</span><br></pre></td></tr></table></figure>

<p><img src="https://gitee.com/godzeo/blogimg/raw/master/img/20220117161600.png" alt="image-20220117161600498"></p>
<h3 id="2、修改-config-json"><a href="#2、修改-config-json" class="headerlink" title="2、修改 config.json"></a>2、修改 config.json</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">vim config.json</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/d8e75edd90559295165af0b4dfb4f3e4.png" alt="image-20220117161759312"></p>
<ul>
<li><p>admin_server 把 127.0.0.1 改为 0.0.0.0,外网直接访问就要0.0.0.0</p>
</li>
<li><p>listen_url也要是0.0.0.0:81，我的80端口被占用了，所以改81</p>
</li>
</ul>
<h3 id="3、运行"><a href="#3、运行" class="headerlink" title="3、运行"></a>3、运行</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line">chmod u+x gophish</span><br><span class="line">./gophish </span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/5eb24b477ee941747fa0256ccbd2ed5c.png" alt="image-20220117162021496"></p>
<p>默认的admin密码再在最后，自己找一下</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/0588860699bb5996ae08cc57164d3e81.png" alt="image-20220117162112606"></p>
<h3 id="4、搭建完成"><a href="#4、搭建完成" class="headerlink" title="4、搭建完成"></a>4、搭建完成</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">https://VPS-IP:3333/</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/c135a40a5ee475350fa3b4888e18521d.png" alt="image-20220117162338519"></p>
<p>也可以直接使用公共邮箱，去开通一下就好了。但是发多了会被封的，所以我们还是自己搭。</p>
<h1 id="0x02-购买域名"><a href="#0x02-购买域名" class="headerlink" title="0x02 购买域名"></a>0x02 购买域名</h1><p>建议使用国外的域名和云vps</p>
<p>要自己去弄一个近似域名发件人去发一些钓鱼邮件，这个自己购买吧</p>
<p>在此近似域名的DNS管理页面增加两条记录:</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/ff88892b0c54db5123ed2248a03b4084.png" alt="image-20220117160858770"></p>
<h1 id="0x03-邮件服务器的搭建"><a href="#0x03-邮件服务器的搭建" class="headerlink" title="0x03 邮件服务器的搭建"></a>0x03 邮件服务器的搭建</h1><ul>
<li>公共邮箱其实也是可以，但是发多了会被封的，所以我们还是自己搭。</li>
<li>由于我的VPS一直是Ubuntu，所以选择使用 Postfix+mailutils</li>
</ul>
<p>（如果是centos，有更好用的平台EwoMail搭建，参考官方文档进行一步步搭建<a target="_blank" rel="noopener" href="http://doc.ewomail.com/docs/ewomail/install%EF%BC%89">http://doc.ewomail.com/docs/ewomail/install）</a></p>
<h3 id="1、安装Postfix"><a href="#1、安装Postfix" class="headerlink" title="1、安装Postfix"></a>1、安装Postfix</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">apt install postfix</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/0e43ca140c4dd16dbc0afe926cf3220d.png" alt="image-20220117160043668"></p>
<p>写入自己域名，不需要前缀</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/bccd1da41b6ea5d6e7e61ed88a94b052.png" alt="image-20220117102647996"></p>
<h3 id="2、安装mailx软件包"><a href="#2、安装mailx软件包" class="headerlink" title="2、安装mailx软件包"></a>2、安装mailx软件包</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">apt install mailutils</span><br></pre></td></tr></table></figure>

<h3 id="3、增加测试用户"><a href="#3、增加测试用户" class="headerlink" title="3、增加测试用户"></a>3、增加测试用户</h3><p>这个用户就是将来收发邮件那个同名用户</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line">useradd -m -s /bin/bash master</span><br><span class="line">passwd master</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/6dd2e0eb30b519f97cb8c6c4db18c8b2.png" alt="image-20220117103020892"></p>
<h3 id="4、测试邮件发送"><a href="#4、测试邮件发送" class="headerlink" title="4、测试邮件发送"></a>4、测试邮件发送</h3><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br><span class="line">9</span><br><span class="line">10</span><br><span class="line">11</span><br><span class="line">12</span><br><span class="line">13</span><br><span class="line">14</span><br><span class="line">15</span><br><span class="line">16</span><br><span class="line">17</span><br><span class="line">18</span><br><span class="line">19</span><br><span class="line">20</span><br><span class="line">21</span><br><span class="line">22</span><br><span class="line">23</span><br><span class="line">24</span><br><span class="line">25</span><br><span class="line">26</span><br><span class="line">27</span><br><span class="line">28</span><br><span class="line">29</span><br><span class="line">30</span><br></pre></td><td class="code"><pre><span class="line">root@10-7-21-215:~# telnet localhost 25</span><br><span class="line">Trying ::1...</span><br><span class="line">Connected to localhost.</span><br><span class="line">Escape character is &#x27;^]&#x27;.</span><br><span class="line">220 10-7-21-215 ESMTP Postfix (Ubuntu)</span><br><span class="line">ehlo localhost</span><br><span class="line">250-10-7-21-215</span><br><span class="line">250-PIPELINING</span><br><span class="line">250-SIZE 10240000</span><br><span class="line">250-VRFY</span><br><span class="line">250-ETRN</span><br><span class="line">250-STARTTLS</span><br><span class="line">250-ENHANCEDSTATUSCODES</span><br><span class="line">250-8BITMIME</span><br><span class="line">250-DSN</span><br><span class="line">250 SMTPUTF8</span><br><span class="line">mail from:master@icbxxxxices.ml</span><br><span class="line">250 2.1.0 Ok</span><br><span class="line">rcpt to:123456@qq.com</span><br><span class="line">250 2.1.5 Ok</span><br><span class="line">data</span><br><span class="line">354 End data with &lt;CR&gt;&lt;LF&gt;.&lt;CR&gt;&lt;LF&gt;</span><br><span class="line">Subject:this is test qq mail</span><br><span class="line">qqqq</span><br><span class="line">ssss</span><br><span class="line">.</span><br><span class="line">250 2.0.0 Ok: queued as 09B30C444A</span><br><span class="line">quit</span><br><span class="line">221 2.0.0 Bye</span><br><span class="line">Connection closed by foreign host.</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/ffe9acbfe78571c9eeefb478dea1da76.png" alt="image-20220117160745104"></p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/4d7ac2ca45c6035ed86fe3130aaaa87e.png" alt="image-20220117160726281"></p>
<h3 id="5、收到测试邮件"><a href="#5、收到测试邮件" class="headerlink" title="5、收到测试邮件"></a>5、收到测试邮件</h3><p><img src="https://img-blog.csdnimg.cn/img_convert/cc6e08529049274773e743edea110789.png" alt="image-20220117160654796"></p>
<h3 id="6、回复一下邮件，可以接受邮件"><a href="#6、回复一下邮件，可以接受邮件" class="headerlink" title="6、回复一下邮件，可以接受邮件"></a>6、回复一下邮件，可以接受邮件</h3><p>切换用户看一下</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br></pre></td><td class="code"><pre><span class="line">su - master</span><br><span class="line">mail</span><br></pre></td></tr></table></figure>

<p><img src="https://img-blog.csdnimg.cn/img_convert/aa038c1aec0ee43169a352b2758c8bc3.png" alt="image-20220117114317418"></p>
<h3 id="7、邮件服务器done"><a href="#7、邮件服务器done" class="headerlink" title="7、邮件服务器done"></a>7、邮件服务器done</h3><h1 id="0x04-实战钓鱼"><a href="#0x04-实战钓鱼" class="headerlink" title="0x04 实战钓鱼"></a>0x04 实战钓鱼</h1><p>环境搭建好了，那么下面就开始正式钓鱼了</p>
<h2 id="1、Sending-Profiles-邮箱配置"><a href="#1、Sending-Profiles-邮箱配置" class="headerlink" title="1、Sending Profiles-邮箱配置"></a>1、Sending Profiles-邮箱配置</h2><p>使用本机刚刚陪着好邮件服务器</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/0f7054301f79298645f9659ef5fd7caf.png" alt="image-20220117172647005"></p>
<p><strong>此处需要注意的是Host处：</strong></p>
<ul>
<li>因为大部分的国内云厂商因为 监管要求，为防止邮件泛滥，都将25端口禁用了，因此可采用带有SSL的SMTP服务的端 口：465端口。</li>
<li>我能用是因为，我用的vps是国外的，大家自行更改。</li>
<li>因为我们的 Gophish 服务器跟邮件服务器搭在同一台 VPS 上面，所以在这里填写 127.0.0.1</li>
</ul>
<h3 id="发送测试一下"><a href="#发送测试一下" class="headerlink" title="发送测试一下"></a>发送测试一下</h3><p><img src="https://img-blog.csdnimg.cn/img_convert/9e2797d4939eaaf1b91cdfa2ff027048.png" alt="image-20220117172859038"></p>
<h3 id="收到邮件"><a href="#收到邮件" class="headerlink" title="收到邮件"></a>收到邮件</h3><p><img src="https://img-blog.csdnimg.cn/img_convert/dbb44453910a330c0ad4e665253cd172.png" alt="image-20220117173154818"></p>
<h2 id="2、Email-Templates-钓鱼邮件模板"><a href="#2、Email-Templates-钓鱼邮件模板" class="headerlink" title="2、Email Templates-钓鱼邮件模板"></a>2、Email Templates-钓鱼邮件模板</h2><p>第一种自己写</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/3a69bc02c591e26c1c0bb474449b0132.png" alt="image-20220117173838799"></p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br><span class="line">9</span><br><span class="line">10</span><br><span class="line">11</span><br><span class="line">12</span><br><span class="line">13</span><br></pre></td><td class="code"><pre><span class="line">&lt;html&gt;</span><br><span class="line">&lt;head&gt;</span><br><span class="line">	&lt;title&gt;&lt;/title&gt;</span><br><span class="line">&lt;/head&gt;</span><br><span class="line">&lt;body&gt;</span><br><span class="line">&lt;p&gt;您好：&lt;/p&gt;</span><br><span class="line"></span><br><span class="line">&lt;p&gt;近期检测到您在学者网教学科研协作单位平台的密码已过期， 请点击&lt;a href=&quot;&#123;&#123;.URL&#125;&#125;&quot;&gt;此链接&lt;/a&gt;尽快修改密码，谢谢配合！&lt;/p&gt;</span><br><span class="line">&#123;&#123;.Tracker&#125;&#125;&lt;/body&gt;</span><br><span class="line"></span><br><span class="line">&lt;p&gt;请不要直接回复本邮件。&lt;/p&gt;</span><br><span class="line">&lt;p&gt;学信网&lt;/p&gt;</span><br><span class="line">&lt;/html&gt;</span><br></pre></td></tr></table></figure>

<p>第二种可以导入现有的邮件</p>
<p>首先将原有的邮件导出为eml格式。</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/6e8b8c6af1a5626bf2a05c97b4c6f60c.png" alt="image-20220117174448234"></p>
<p>导入即可</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/e735df23c718d41b25fe79163b43d2ec.png" alt="image-20220117174400492"></p>
<p>把超链接的部分，加上URL标签，最后设置钓鱼页面</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/84ef1fb1a81f06626a878f41c0d7ad05.png" alt="image-20220117174749203"></p>
<h2 id="3、Landing-Pages-伪造钓鱼页面"><a href="#3、Landing-Pages-伪造钓鱼页面" class="headerlink" title="3、Landing Pages-伪造钓鱼页面"></a>3、Landing Pages-伪造钓鱼页面</h2><p>配置好钓鱼邮件后，就可以通过LandingPages模块来新建钓鱼网站页面。</p>
<p>1、此处支持手写 html文件</p>
<p>2、直接克隆网站</p>
<p>我使用第二种：</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/a50b70955b54cacf4a1794850d2688cf.png" alt="image-20220117175521760"></p>
<p>其中选项：</p>
<ul>
<li>CaptureSubmitted Data和CapturePasswords，记录受害者输入的账号和密码。</li>
<li>Redirect to填写该页面真实的地址，方便受害者点击完提交按钮后，自动跳转至真正的网站。</li>
</ul>
<h2 id="4、Users-amp-Groups-邮件用户和组"><a href="#4、Users-amp-Groups-邮件用户和组" class="headerlink" title="4、Users&amp; Groups-邮件用户和组"></a>4、Users&amp; Groups-邮件用户和组</h2><p>此时就可以进行下一步的配置，设置要进行钓鱼攻击的邮箱地址</p>
<p>使用模版批量导入，导入邮箱可以使用CSV进行批量添加</p>
<p>(格式可点击<code>Download CSV TEmplate</code>获取模板)</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/8a34e904738416ea8c290657818ad149.png" alt="image-20220117175956861"></p>
<h2 id="5、Campaigns-钓鱼测试"><a href="#5、Campaigns-钓鱼测试" class="headerlink" title="5、Campaigns-钓鱼测试"></a>5、Campaigns-钓鱼测试</h2><p>配置Campaigns，填写Name、选择钓鱼邮件模板、选择钓鱼网站模板、填写钓鱼网站 URL、填写发件邮箱、选择受害者邮件组。</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/85df2c9dfdeee9b09d04b774e40ce3e4.png" alt="image-20220117180250617"></p>
<p>注意这个URL是VPS上gophish一开始配置的那个</p>
<p>就是 <a target="_blank" rel="noopener" href="http://vps-ip:81/">http://vps-ip:81</a></p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/8040e0335371b0ce830434dcf05afbff.png" alt="image-20220117180454331"></p>
<h2 id="6、查看战果"><a href="#6、查看战果" class="headerlink" title="6、查看战果"></a>6、查看战果</h2><p>这里有全部任务的统计</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/70fa1b66102aab96213d96520281fbce.png" alt="image-20220117190809333"></p>
<h2 id="7、打开详细内容"><a href="#7、打开详细内容" class="headerlink" title="7、打开详细内容"></a>7、打开详细内容</h2><p>可以看到发送成功的邮件、打开邮件的情况、点击链接的情况、提交数据的情况</p>
<p><img src="https://img-blog.csdnimg.cn/img_convert/0c0676d59f3def6227b1500b131c39a7.png" alt="image-20220117180333865"></p>
<h1 id="0x05-总结"><a href="#0x05-总结" class="headerlink" title="0x05 总结"></a>0x05 总结</h1><p>这个只是邮件钓鱼的基础设施搭建，和基本使用方式，后续还有很多要点，木马免杀、钓鱼话术、邮箱收集等等。。。还有就是通过IM的方式也是十分有效的，后续再说。</p>
</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta">文章作者: </span><span class="post-copyright-info"><a href="https://godzeo.github.io">Zeo</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta">文章链接: </span><span class="post-copyright-info"><a href="https://godzeo.github.io/2022/01/20/%E9%92%93%E9%B1%BC%E6%8C%87%E5%8C%97%20Gophish%E9%92%93%E9%B1%BC%E5%B9%B3%E5%8F%B0%E5%92%8C%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA/">https://godzeo.github.io/2022/01/20/%E9%92%93%E9%B1%BC%E6%8C%87%E5%8C%97%20Gophish%E9%92%93%E9%B1%BC%E5%B9%B3%E5%8F%B0%E5%92%8C%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA/</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta">版权声明: </span><span class="post-copyright-info">本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/" target="_blank">CC BY-NC-SA 4.0</a> 许可协议。转载请注明来自 <a href="https://godzeo.github.io" target="_blank">Zeo's Security Lab</a>！</span></div></div><div class="tag_share"><div class="post-meta__tag-list"><a class="post-meta__tags" href="/tags/%E6%9C%8D%E5%8A%A1%E5%99%A8-%E8%BF%90%E7%BB%B4-%E5%AE%89%E5%85%A8/">服务器 运维 安全</a></div><div class="post_share"><div class="social-share" data-image="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/js/social-share.min.js" defer></script></div></div><nav class="pagination-post" id="pagination"><div class="prev-post pull-left"><a href="/2022/01/26/CVE-2021-4034%20Linux%20Polkit%20pkexec%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E/"><img class="prev-cover" src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225559.webp" onerror="onerror=null;src='/img/404.jpg'" alt="cover of previous post"><div class="pagination-info"><div class="label">上一篇</div><div class="prev_info">CVE-2021-4034 Linux Polkit pkexec权限提升漏洞</div></div></a></div><div class="next-post pull-right"><a href="/2021/12/24/docker%20denied!%20requested%20access%20to%20the%20resource%20is%20denied/"><img class="next-cover" src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">下一篇</div><div class="next_info">docker denied/ requested access to the resource is denied</div></div></a></div></nav></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231013354.png" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">Zeo</div><div class="author-info__description">专注于安全,分享生活,分享知识</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">125</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">46</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">9</div></a></div><a id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/godzeo"><i class="fab fa-github"></i><span>Follow Me</span></a><div class="card-info-social-icons is-center"><a class="social-icon" href="https://github.com/godzeo" target="_blank" title="Github"><i class="fab fa-github"></i></a><a class="social-icon" href="mailto:zzzhhhaaaiiii@gmail.com" target="_blank" title="Email"><i class="fas fa-envelope"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>公告</span></div><div class="announcement_content">Weclome my blog</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>目录</span><span class="toc-percentage"></span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-1"><a class="toc-link" href="#0x00-%E6%94%BB%E9%98%B2%E6%BC%94%E7%BB%83%E9%92%93%E9%B1%BC"><span class="toc-number">1.</span> <span class="toc-text">0x00 攻防演练钓鱼</span></a></li><li class="toc-item toc-level-1"><a class="toc-link" href="#0x01-%E6%90%AD%E5%BB%BAGophish%E9%92%93%E9%B1%BC%E5%B9%B3%E5%8F%B0"><span class="toc-number">2.</span> <span class="toc-text">0x01 搭建Gophish钓鱼平台</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#1%E3%80%81%E4%B8%8B%E8%BD%BD"><span class="toc-number">2.0.1.</span> <span class="toc-text">1、下载</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#2%E3%80%81%E4%BF%AE%E6%94%B9-config-json"><span class="toc-number">2.0.2.</span> <span class="toc-text">2、修改 config.json</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#3%E3%80%81%E8%BF%90%E8%A1%8C"><span class="toc-number">2.0.3.</span> <span class="toc-text">3、运行</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#4%E3%80%81%E6%90%AD%E5%BB%BA%E5%AE%8C%E6%88%90"><span class="toc-number">2.0.4.</span> <span class="toc-text">4、搭建完成</span></a></li></ol></li></ol></li><li class="toc-item toc-level-1"><a class="toc-link" href="#0x02-%E8%B4%AD%E4%B9%B0%E5%9F%9F%E5%90%8D"><span class="toc-number">3.</span> <span class="toc-text">0x02 购买域名</span></a></li><li class="toc-item toc-level-1"><a class="toc-link" href="#0x03-%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%9A%84%E6%90%AD%E5%BB%BA"><span class="toc-number">4.</span> <span class="toc-text">0x03 邮件服务器的搭建</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#1%E3%80%81%E5%AE%89%E8%A3%85Postfix"><span class="toc-number">4.0.1.</span> <span class="toc-text">1、安装Postfix</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#2%E3%80%81%E5%AE%89%E8%A3%85mailx%E8%BD%AF%E4%BB%B6%E5%8C%85"><span class="toc-number">4.0.2.</span> <span class="toc-text">2、安装mailx软件包</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#3%E3%80%81%E5%A2%9E%E5%8A%A0%E6%B5%8B%E8%AF%95%E7%94%A8%E6%88%B7"><span class="toc-number">4.0.3.</span> <span class="toc-text">3、增加测试用户</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#4%E3%80%81%E6%B5%8B%E8%AF%95%E9%82%AE%E4%BB%B6%E5%8F%91%E9%80%81"><span class="toc-number">4.0.4.</span> <span class="toc-text">4、测试邮件发送</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#5%E3%80%81%E6%94%B6%E5%88%B0%E6%B5%8B%E8%AF%95%E9%82%AE%E4%BB%B6"><span class="toc-number">4.0.5.</span> <span class="toc-text">5、收到测试邮件</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#6%E3%80%81%E5%9B%9E%E5%A4%8D%E4%B8%80%E4%B8%8B%E9%82%AE%E4%BB%B6%EF%BC%8C%E5%8F%AF%E4%BB%A5%E6%8E%A5%E5%8F%97%E9%82%AE%E4%BB%B6"><span class="toc-number">4.0.6.</span> <span class="toc-text">6、回复一下邮件，可以接受邮件</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#7%E3%80%81%E9%82%AE%E4%BB%B6%E6%9C%8D%E5%8A%A1%E5%99%A8done"><span class="toc-number">4.0.7.</span> <span class="toc-text">7、邮件服务器done</span></a></li></ol></li></ol></li><li class="toc-item toc-level-1"><a class="toc-link" href="#0x04-%E5%AE%9E%E6%88%98%E9%92%93%E9%B1%BC"><span class="toc-number">5.</span> <span class="toc-text">0x04 实战钓鱼</span></a><ol class="toc-child"><li class="toc-item toc-level-2"><a class="toc-link" href="#1%E3%80%81Sending-Profiles-%E9%82%AE%E7%AE%B1%E9%85%8D%E7%BD%AE"><span class="toc-number">5.1.</span> <span class="toc-text">1、Sending Profiles-邮箱配置</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#%E5%8F%91%E9%80%81%E6%B5%8B%E8%AF%95%E4%B8%80%E4%B8%8B"><span class="toc-number">5.1.1.</span> <span class="toc-text">发送测试一下</span></a></li><li class="toc-item toc-level-3"><a class="toc-link" href="#%E6%94%B6%E5%88%B0%E9%82%AE%E4%BB%B6"><span class="toc-number">5.1.2.</span> <span class="toc-text">收到邮件</span></a></li></ol></li><li class="toc-item toc-level-2"><a class="toc-link" href="#2%E3%80%81Email-Templates-%E9%92%93%E9%B1%BC%E9%82%AE%E4%BB%B6%E6%A8%A1%E6%9D%BF"><span class="toc-number">5.2.</span> <span class="toc-text">2、Email Templates-钓鱼邮件模板</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#3%E3%80%81Landing-Pages-%E4%BC%AA%E9%80%A0%E9%92%93%E9%B1%BC%E9%A1%B5%E9%9D%A2"><span class="toc-number">5.3.</span> <span class="toc-text">3、Landing Pages-伪造钓鱼页面</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#4%E3%80%81Users-amp-Groups-%E9%82%AE%E4%BB%B6%E7%94%A8%E6%88%B7%E5%92%8C%E7%BB%84"><span class="toc-number">5.4.</span> <span class="toc-text">4、Users&amp; Groups-邮件用户和组</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#5%E3%80%81Campaigns-%E9%92%93%E9%B1%BC%E6%B5%8B%E8%AF%95"><span class="toc-number">5.5.</span> <span class="toc-text">5、Campaigns-钓鱼测试</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#6%E3%80%81%E6%9F%A5%E7%9C%8B%E6%88%98%E6%9E%9C"><span class="toc-number">5.6.</span> <span class="toc-text">6、查看战果</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#7%E3%80%81%E6%89%93%E5%BC%80%E8%AF%A6%E7%BB%86%E5%86%85%E5%AE%B9"><span class="toc-number">5.7.</span> <span class="toc-text">7、打开详细内容</span></a></li></ol></li><li class="toc-item toc-level-1"><a class="toc-link" href="#0x05-%E6%80%BB%E7%BB%93"><span class="toc-number">6.</span> <span class="toc-text">0x05 总结</span></a></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2022/11/28/Nosql%20inject%E6%B3%A8%E5%85%A5/" title="Nosql inject注入"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Nosql inject注入"/></a><div class="content"><a class="title" href="/2022/11/28/Nosql%20inject%E6%B3%A8%E5%85%A5/" title="Nosql inject注入">Nosql inject注入</a><time datetime="2022-11-28T07:28:02.000Z" title="发表于 2022-11-28 15:28:02">2022-11-28</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/11/15/%E4%BC%81%E4%B8%9A%20SDLC%20%E5%AE%89%E5%85%A8%E7%94%9F%E5%91%BD%E5%91%A8%E6%9C%9F%E7%AE%A1%E7%90%86/" title="企业 SDLC 安全生命周期管理"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="企业 SDLC 安全生命周期管理"/></a><div class="content"><a class="title" href="/2022/11/15/%E4%BC%81%E4%B8%9A%20SDLC%20%E5%AE%89%E5%85%A8%E7%94%9F%E5%91%BD%E5%91%A8%E6%9C%9F%E7%AE%A1%E7%90%86/" title="企业 SDLC 安全生命周期管理">企业 SDLC 安全生命周期管理</a><time datetime="2022-11-15T14:03:44.000Z" title="发表于 2022-11-15 22:03:44">2022-11-15</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/11/05/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E6%BC%8F%E6%B4%9E(File%20Operation!Redirect!Cors)/" title="Go 代码审计漏洞(File Operation\Redirect\Cors)"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Go 代码审计漏洞(File Operation\Redirect\Cors)"/></a><div class="content"><a class="title" href="/2022/11/05/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E6%BC%8F%E6%B4%9E(File%20Operation!Redirect!Cors)/" title="Go 代码审计漏洞(File Operation\Redirect\Cors)">Go 代码审计漏洞(File Operation\Redirect\Cors)</a><time datetime="2022-11-05T09:15:28.000Z" title="发表于 2022-11-05 17:15:28">2022-11-05</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/10/30/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E(sqli!cmd!ssrf)/" title="Go 代码审计高危漏洞(sqli\cmd\ssrf)"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Go 代码审计高危漏洞(sqli\cmd\ssrf)"/></a><div class="content"><a class="title" href="/2022/10/30/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E(sqli!cmd!ssrf)/" title="Go 代码审计高危漏洞(sqli\cmd\ssrf)">Go 代码审计高危漏洞(sqli\cmd\ssrf)</a><time datetime="2022-10-30T06:57:14.000Z" title="发表于 2022-10-30 14:57:14">2022-10-30</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/05/10/Java%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%EF%BC%9A%20ClassLoader%E5%BA%94%E7%94%A8/" title="Java代码审计： ClassLoader应用"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Java代码审计： ClassLoader应用"/></a><div class="content"><a class="title" href="/2022/05/10/Java%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%EF%BC%9A%20ClassLoader%E5%BA%94%E7%94%A8/" title="Java代码审计： ClassLoader应用">Java代码审计： ClassLoader应用</a><time datetime="2022-05-10T08:21:21.000Z" title="发表于 2022-05-10 16:21:21">2022-05-10</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2019 - 2022 By Zeo</div><div class="footer_custom_text">Hi, welcome to my blog!</div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="阅读模式"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="目录"><i class="fas fa-list-ul"></i></button><button id="go-up" type="button" title="回到顶部"><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.umd.min.js"></script><div class="js-pjax"></div></div></body></html>